¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180807
°ä²¼¹¦·ò 2018-08-07¡¾·ÖÎö»ã±¨¡¿ICS-CERT°ä²¼ÁªÍøµçÁ¦ÏµÍ³ÍøÂç°²È«Ì¬ÊÆ·ÖÎö»ã±¨
CNCERTÏÂÊôµÄ¹¤Òµ»¥ÁªÍø°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨ICS-CERT£©Õë¶ÔÎÒ¹úÁªÍøµçÁ¦ÏµÍ³µÄÍøÂç°²È«Ì¬ÊÆ½øÐзÖÎö£¬2018Äê1-2¼¾¶ÈÆÚ¼ä¼à²â·¢ÏÖ¶³öÔÚ¹«¹²»¥ÁªÍøµÄµçÁ¦ÐÐÒµÍøÂç×ʲú1147¸ö£¬²¿ÃÅÉ豸´æÔÚÑϳÁµÄ°²È«·ì϶¡£Í¨¹ýÒýÈëÁªÍøµçÁ¦ÏµÍ³ÍøÂ簲ȫÍþвָÊý£¬´ÓÉ豸×ʲúºÍWEB×ʲúÁ½¸ö½Ç¶È£¬½áºÏ·ì϶ÍþвµÈ¼¶¡¢Ì½²â´ÎÊýºÍ¹¥»÷´ÎÊý£¬¶ÔÎÒ¹ú·ÖÆçµØÓòµÄÁªÍøµçÁ¦ÏµÍ³°²È«ÍþвָÊý½øÐÐÁË×ۺϷÖÎö£¬·¢ÏÖÎÞÊýÊ¡·ÝÇé¿öÓÅÁ¼£¬¶ø¹ã¶«¡¢±±¾©µÈÊ¡Êа²È«´ó¾ÖÏà¶ÔÑϸñ¡£
ÔÎÄÁ´½Ó£ºhttps://www.ics-cert.org.cn/portal/page/121/95290efb86b44d7d8cd7ee222f3e9e24.html
¡¾·ÖÎö»ã±¨¡¿×êÑлú¹¹°ä²¼2018ÄêQ2ÍøÂçÍþвÇ÷ÏòµÄ·ÖÎö»ã±¨
¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¹ØÓÚ2018ÄêQ2ÍøÂçÍþвÇ÷ÏòµÄͳ¼Æ»ã±¨£¬»ã±¨º¸ÇÁ˵ڶþ¼¾¶ÈµÄÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯£¬ÈçOperation Parliament¡¢APT×éÖ¯Energetic Bear¡¢Òƶ¯ÍþвZooPark¡¢Õë¶Ô·ÓÉÆ÷µÄ½©Ê¬ÍøÂçVPNFilter¡¢Õë¶ÔÖÐÑÇÊý¾ÝÖÐÐĵÄLuckyMouseÒÔ¼°Õë¶ÔÅ·ÖÞ½ðÈÚ»ú¹¹ºÍÉúÎï×éÖ¯µÄOlympic Destroyer¡£»ã±¨»¹º¸ÇÁ˲¿ÃŶñÒâÈí¼þ¼°Æäм¼Êõ£¬ÈçSynAckºÍRoaming MantisµÈ¡£
ÔÎÄÁ´½Ó£ºhttps://securelist.com/it-threat-evolution-q2-2018/87172/
¡¾Íþвµý±¨¡¿FBI°ä²¼°²È«²¼¸æ¾¯Ê¾ÎïÁªÍøÉ豸Öеݲȫ·çÏÕ
ÃÀ¹úFBIÖÒ¸æ³ÆÓû§µÄÎïÁªÍøÉ豸¿ÉÄÜÒѱ»ÊÕÊÜ£¬ÕâЩIoT½©Ê¬ÍøÂç±»ÓÃÓÚÌáÒéDDoS¹¥»÷µÈ¡£´Ó·ÓÉÆ÷ºÍNASÉ豸µ½DVR¡¢Ê÷Ý®ÅÉÉõÖÁÊÇÖÇÄܳµ¿â£¬ËùÓÐIoTÉ豸¶¼¿ÉÄÜÃæ¶Ô·çÏÕ¡£¿ÉÒɵļ£ÏóÔ̺¬»¥ÁªÍøÔÂʹÓÃÁ¿µÄ´ó·ùÔö³¤¡¢¸ß¶îµÄISPÕ˵¥¡¢É豸ÔËÐлºÂý»òÎÞ·¨ÔËÐÓ×¢DNS²éÎʺÍÁ÷Á¿Òì³£ÒÔ¼°ÍøÂçÏνӿìÂÊÂýµÈ¡£¹¥»÷Õßͨ³£»áÕë¶ÔÓµÓÐÈõ¿ÚÁ佨¸´µÄ¹Ì¼þ»òÈí¼þ·ì϶ÒÔ¼°Ê¹ÓÃĬÈÏÓû§ÃûºÍÃÜÂëµÄÉ豸½øÐб©Á¦¹¥»÷¡£
ÔÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/fbi-in-smart-device-security/
¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖϰȾ³¬¹ý10ÍòÌ¨ÍÆËã»úµÄ½©Ê¬ÍøÂçBlack
Check Point×êÑÐÍŶӷ¢ÏÖÒøÐжñÒâÈí¼þRamnitµÄеĴó¹æÄ£¹¥»÷»î¶¯£¬ÔÚ2018Äê5ÔÂÖÁ7ÔÂÆÚ¼äÒÔ185.44.75.109ΪC&C·þÎñÆ÷µÄ½©Ê¬ÍøÂçBlackϰȾÁ˳¬¹ý10ÍòÌ¨ÍÆËã»ú¡£¸Ã½©Ê¬ÍøÂçµÄÌØµãÔ̺¬£º´óÁ¿Ñù±¾Ê¹ÓÃÓ²±àÂëµÄÓòÃû¶ø²»ÊÇDGA£»C£¦C·þÎñÆ÷²¢²»Ìṩ¶î±íµÄÄ£¿é£¬ÈçVNC¡¢ÃÜÂëÇÔÈ¡·¨Ê½»òFtpGrabberµÈ£»¶î±íµÄÄ£¿é£¨FTPServer¡¢WebInjects£©ÓëRamnit¼¯³ÉÔÚÒ»¸ö°üÖУ»Ramnit×÷ΪÁíÒ»¸ö¶ñÒâÈí¼þNgiowebµÄ¼ÓÔØ·¨Ê½¡£½ØÖÁ2018Äê7Ô³õ£¬Ï°È¾ÁËNgiowebµÄÍÆËã»úÊýÁ¿³¬¹ýÁË13.9Íǫ̀¡£
ÔÎÄÁ´½Ó£ºhttps://research.checkpoint.com/ramnits-network-proxy-servers/
¡¾·ì϶²¹¶¡¡¿HP°ä²¼InkJet´òÓ¡»úµÄ¹Ì¼þ¸üУ¬½¨¸´Á½¸ö¿Éµ¼ÖÂRCEµÄ°²È«·ì϶
»ÝÆÕ°ä²¼InkJet´òÓ¡»úµÄ¹Ì¼þ¸üУ¬½¨¸´ÁËÁ½¸ö°²È«·ì϶£¨CVE-2018-5924ºÍCVE-2018-5925£©¡£ÕâÁ½¸ö·ì϶¿Éͨ¹ý·¢ËÍÖÁÖ¸±êÉ豸µÄ¶ñÒâÎļþ´¥·¢£¬µ¼Ö²ֿâ»ò¾²Ì¬»º³åÇøÒç³ö£¬×îÖÕÔÊÐíÔ¶³Ì´úÂëÖ´ÐС£ÊÜÓ°ÏìµÄÉ豸Ô̺¬Pagewide Pro¡¢DesignJet¡¢OfficeJet¡¢DeskJetºÍEnvyϵÁеȡ£½¨ÒéÓû§¾¡¿ì×°ÖÃÕâЩ¹Ì¼þ¸üС£
ÔÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2018/08/06/hp-inkjet-printer-vulnerabilities/
¡¾¶ñÒâÈí¼þ¡¿°²È«×êÑÐÈËÔ±·¢ÏÖжñÒâÍÚ¿óÈí¼þZombieBoy
°²È«×êÑÐÈËÔ±James Quinn·¢ÏÖеÄÍÚ¿óÈ䳿ZombieBoy£¬¸Ã¶ñÒâÍÚ¿óÈí¼þ¿ÉΪÆä×÷Õß´øÀ´Ã¿Ô¼ÛÖµÔ¼1000ÃÀÔªµÄÃÅÂÞ±Ò¡£ZombieBoyÀûÓõķì϶Ô̺¬RDP·ì϶CVE-2017-9073¡¢SMB·ì϶CVE-2017-0143ºÍCVE-2017-0146µÈ£¬Ò»µ©ÔÚÖ¸±êϵͳÖгÉÁ¢Á˺óÃÅ£¬Ëü¾ÍÄܹ»½øÒ»²½ÌṩÆäËü¶ñÒâÈí¼þ£¬ÈçÀÕË÷Èí¼þ»ò¼üÅ̼ͼ·¨Ê½µÈ¡£×êÑÐÈËÔ±Åû¶Á˹ØÓÚZombieBoyµÄ¸ü¶àIoC¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75070/malware/zombieboy-monero-miner.html


¾©¹«Íø°²±¸11010802024551ºÅ